CVE-2026-9818: Roundcube Local/Private URL Fetch Bypass
Published May 28, 2026
·Updated
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Affected Software
1 affected component
Roundcube Roundcube
Remediation
Information
Upgrade to Roundcube Webmail 1.6.16 or 1.7.1
Event History
May 28, 2026
CVE Published
via MITRE·12:16 PM
Rejected
via MITRE·12:16 PM
Data Sourced
via NVD·01:16 PM
Description
Rejected
via MITRE·04:35 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-9818?
CVE-2026-9818 has a medium severity score of 4.7.
2
How do I fix CVE-2026-9818?
To fix CVE-2026-9818, upgrade to Roundcube Webmail versions 1.6.16 or 1.7.1.
3
What type of attack is associated with CVE-2026-9818?
CVE-2026-9818 allows remote attackers to bypass URL fetch restrictions and send requests to local or private-network services.
4
Which versions of Roundcube are affected by CVE-2026-9818?
CVE-2026-9818 affects earlier versions of Roundcube prior to 1.6.16 and 1.7.1.
5
What kind of URLs can be exploited in CVE-2026-9818?
CVE-2026-9818 allows the use of loopback, localhost, RFC1918, link-local, and ULA URLs.